spark-design-system icon indicating copy to clipboard operation
spark-design-system copied to clipboard

[Snyk] Security upgrade gatsby from 2.23.3 to 3.14.0

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Open Redirect
SNYK-JS-GOT-2932019
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gatsby The new version differs by 250 commits.
  • f3f1bbc chore(release): Publish
  • c410082 fix(gatsby-source-drupal): check relationships type exists on node before filtering (#33181) (#33228)
  • f3f2834 fix(gatsby-source-wordpress): fix failing test docker setup (#33163)
  • fe2f09b feat(gatsby): let serve use getServerData headers (#33159)
  • fc66250 fix(gatsby): Assign parentSpan to activities that were missing them (#33122)
  • 91187da feat(gatsby-source-drupal): Add tracing for full/delta fetches and http requests (#33142)
  • d31645c chore(gatsby): add webpack file to export same version (#33126)
  • 44afaf5 fix(gatsby): fix hydration flicker on initial render of ssr page (#33134)
  • f1141a0 docs: Fix broken link on Getting Started with MDX page (#33148)
  • f921277 chore(release): Publish next
  • b1168af chore(gatsby-plugin-gatsby-cloud): fix copy type file (#33156)
  • 14059da Remove <title> from inside <main> (#33150)
  • 85645cd chore(release): Publish next
  • 1720988 feat(gatsby-transformer-documentationjs): move createTypes to createSchemaCustomization (#33149)
  • 3d05986 feat(gatsby-plugin-styled-components): Add ability to disable vendor prefixes (#33147)
  • 323920d chore(gatsby): add environment variable for setting tracing config file (#32513)
  • 425b8f5 chore(release): Publish next
  • 2f2880e fix(gatsby-source-drupal): handle edge case with deleting nodes (#33143)
  • eb552d1 chore(docs): Add note to Storybook guide about StaticImage (#33127)
  • 4ff5026 docs: fix typo (#33137)
  • 81f35ff docs(gatsby-plugin-gatsby-cloud): fix typo: asterix -> asterisk (#33135)
  • 4837b72 feat(gatsby-plugin-page-creator): Fix gatsby plugin page creator v4 (#33120)
  • 3401149 feat(gatsby): Deprecate schema-related APIs in sourceNodes (#32291)
  • 62683f5 fix(gatsby-plugin-gatsby-cloud): Emit CREATE_FILE_NODE in onPostBootstrap (#33136)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Open Redirect

snyk-bot avatar Jun 20 '22 05:06 snyk-bot